acl_and_auth.go 23 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063
  1. package tool
  2. import (
  3. "database/sql"
  4. "log"
  5. "strconv"
  6. "strings"
  7. "time"
  8. )
  9. func List_acl(func_type string) []string {
  10. if func_type == "user_document" {
  11. return []string{
  12. "",
  13. "user",
  14. "all",
  15. }
  16. } else {
  17. return []string{
  18. "",
  19. "all",
  20. "user",
  21. "admin",
  22. "owner",
  23. "50_edit",
  24. "email",
  25. "ban",
  26. "before",
  27. "30_day",
  28. "90_day",
  29. "ban_admin",
  30. "not_all",
  31. "up_to_level_3",
  32. "up_to_level_10",
  33. "30_day_50_edit",
  34. }
  35. }
  36. }
  37. func Do_insert_auth_history(db *sql.DB, ip string, what string) {
  38. var log_off string
  39. err := db.QueryRow(DB_change("select data from other where name = 'auth_history_off'")).Scan(&log_off)
  40. if err != nil {
  41. if err == sql.ErrNoRows {
  42. log_off = ""
  43. } else {
  44. log.Fatal(err)
  45. }
  46. }
  47. if log_off == "" {
  48. stmt, err := db.Prepare(DB_change("insert into re_admin (who, what, time) values (?, ?, ?)"))
  49. if err != nil {
  50. log.Fatal(err)
  51. }
  52. defer stmt.Close()
  53. time := Get_time()
  54. _, err = stmt.Exec(ip, what, time)
  55. if err != nil {
  56. log.Fatal(err)
  57. }
  58. }
  59. }
  60. func Get_user_auth(db *sql.DB, ip string) string {
  61. if !IP_or_user(ip) {
  62. var auth string
  63. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'acl'"))
  64. if err != nil {
  65. log.Fatal(err)
  66. }
  67. defer stmt.Close()
  68. err = stmt.QueryRow(ip).Scan(&auth)
  69. if err != nil {
  70. if err == sql.ErrNoRows {
  71. auth = "user"
  72. } else {
  73. log.Fatal(err)
  74. }
  75. }
  76. if auth != "user" && auth != "ban" {
  77. return auth
  78. } else {
  79. return ""
  80. }
  81. }
  82. return ""
  83. }
  84. func Get_auth_group_info(db *sql.DB, auth string) map[string]bool {
  85. stmt, err := db.Prepare(DB_change("select acl from alist where name = ?"))
  86. if err != nil {
  87. log.Fatal(err)
  88. }
  89. defer stmt.Close()
  90. rows, err := stmt.Query(auth)
  91. if err != nil {
  92. log.Fatal(err)
  93. }
  94. defer rows.Close()
  95. data_list := map[string]bool{}
  96. for rows.Next() {
  97. var name string
  98. err := rows.Scan(&name)
  99. if err != nil {
  100. log.Fatal(err)
  101. }
  102. data_list[name] = true
  103. }
  104. return Check_auth(data_list)
  105. }
  106. func Check_auth(auth_info map[string]bool) map[string]bool {
  107. if _, ok := auth_info["owner"]; ok {
  108. auth_info["admin"] = true
  109. }
  110. admin_auth := []string{"ban", "toron", "check", "acl", "hidel", "give", "bbs", "vote"}
  111. if _, ok := auth_info["admin"]; ok {
  112. for _, v := range admin_auth {
  113. auth_info[v] = true
  114. }
  115. }
  116. check := false
  117. for _, v := range admin_auth {
  118. if _, ok := auth_info[v]; ok {
  119. check = true
  120. break
  121. }
  122. }
  123. if check {
  124. auth_info["admin_default_feature"] = true
  125. }
  126. admin_default_feature := []string{"treat_as_admin", "user_name_bold", "multiple_upload", "slow_edit_pass", "edit_bottom_compulsion_pass"}
  127. if _, ok := auth_info["admin_default_feature"]; ok {
  128. for _, v := range admin_default_feature {
  129. auth_info[v] = true
  130. }
  131. auth_info["user"] = true
  132. }
  133. return auth_info
  134. }
  135. func Check_acl(db *sql.DB, name string, topic_number string, tool string, ip string) bool {
  136. auth_name := Get_user_auth(db, ip)
  137. auth_info := Get_auth_group_info(db, auth_name)
  138. ip_or_user := IP_or_user(ip)
  139. level := "0"
  140. if !ip_or_user {
  141. level = Get_level(db, ip)[0]
  142. }
  143. level_int, _ := strconv.Atoi(level)
  144. get_ban := ""
  145. ban_type := ""
  146. if tool == "document_edit_request" {
  147. temp_arr := Get_user_ban(db, ip, "edit_request")
  148. get_ban = temp_arr[0]
  149. ban_type = temp_arr[1]
  150. } else {
  151. temp_arr := Get_user_ban(db, ip, "")
  152. get_ban = temp_arr[0]
  153. ban_type = temp_arr[1]
  154. }
  155. if ban_type != "" {
  156. ban_type_len := len(ban_type)
  157. if ban_type_len == 1 {
  158. ban_type = string(ban_type[0])
  159. } else if ban_type_len == 2 {
  160. ban_type = string(ban_type[1])
  161. }
  162. }
  163. if tool == "" && name != "" {
  164. if !Check_acl(db, name, "", "render", ip) {
  165. return false
  166. }
  167. if strings.HasPrefix(name, "user:") {
  168. user_page_str := name[5:]
  169. if slash_index := strings.Index(user_page_str, "/"); slash_index != -1 {
  170. user_page_str = user_page_str[:slash_index]
  171. }
  172. if auth_info["acl"] {
  173. return true
  174. }
  175. if get_ban == "true" {
  176. return false
  177. }
  178. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  179. if err != nil {
  180. log.Fatal(err)
  181. }
  182. defer stmt.Close()
  183. var acl_data string
  184. err = stmt.QueryRow(name).Scan(&acl_data)
  185. if err != nil {
  186. if err == sql.ErrNoRows {
  187. acl_data = ""
  188. } else {
  189. log.Fatal(err)
  190. }
  191. }
  192. if acl_data == "all" {
  193. return true
  194. } else if acl_data == "user" {
  195. if !ip_or_user {
  196. return true
  197. }
  198. } else if ip == user_page_str {
  199. if !ip_or_user {
  200. return true
  201. }
  202. }
  203. return false
  204. }
  205. }
  206. if Arr_in_str([]string{"document_edit", "document_edit_request", "document_move", "document_delete"}, tool) {
  207. if !Check_acl(db, name, topic_number, "", ip) {
  208. return false
  209. }
  210. } else if Arr_in_str([]string{"bbs_edit", "bbs_comment"}, tool) {
  211. if !Check_acl(db, name, topic_number, "bbs_view", ip) {
  212. return false
  213. }
  214. }
  215. if tool == "topic" {
  216. if name == "" {
  217. stmt, err := db.Prepare(DB_change("select title from rd where code = ?"))
  218. if err != nil {
  219. log.Fatal(err)
  220. }
  221. defer stmt.Close()
  222. err = stmt.QueryRow(topic_number).Scan(&name)
  223. if err != nil {
  224. if err == sql.ErrNoRows {
  225. name = "test"
  226. } else {
  227. log.Fatal(err)
  228. }
  229. }
  230. }
  231. }
  232. end_number := 1
  233. for for_a := 0; for_a < end_number; for_a++ {
  234. acl_data := ""
  235. acl_pass_auth := ""
  236. if tool == "all_admin_auth" {
  237. acl_pass_auth = "treat_as_admin"
  238. acl_data = "owner"
  239. } else if tool == "owner_auth" {
  240. acl_pass_auth = "owner"
  241. acl_data = "owner"
  242. } else if tool == "ban_auth" {
  243. acl_pass_auth = "ban"
  244. acl_data = "owner"
  245. } else if tool == "bbs_auth" {
  246. acl_pass_auth = "bbs"
  247. acl_data = "owner"
  248. } else if tool == "toron_auth" {
  249. acl_pass_auth = "toron"
  250. acl_data = "owner"
  251. } else if tool == "check_auth" {
  252. acl_pass_auth = "check"
  253. acl_data = "owner"
  254. } else if tool == "acl_auth" {
  255. acl_pass_auth = "acl"
  256. acl_data = "owner"
  257. } else if tool == "hidel_auth" {
  258. acl_pass_auth = "hidel"
  259. acl_data = "owner"
  260. } else if tool == "give_auth" {
  261. acl_pass_auth = "give"
  262. acl_data = "owner"
  263. } else if tool == "vote_auth" {
  264. acl_pass_auth = "vote_fix"
  265. acl_data = "owner"
  266. } else if tool == "" {
  267. acl_pass_auth = "acl"
  268. if for_a == 0 {
  269. end_number += 1
  270. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'decu'"))
  271. if err != nil {
  272. log.Fatal(err)
  273. }
  274. defer stmt.Close()
  275. err = stmt.QueryRow(name).Scan(&acl_data)
  276. if err != nil {
  277. if err == sql.ErrNoRows {
  278. acl_data = ""
  279. } else {
  280. log.Fatal(err)
  281. }
  282. }
  283. } else {
  284. err := db.QueryRow(DB_change("select data from other where name = 'edit'")).Scan(&acl_data)
  285. if err != nil {
  286. if err == sql.ErrNoRows {
  287. acl_data = ""
  288. } else {
  289. log.Fatal(err)
  290. }
  291. }
  292. }
  293. } else if tool == "document_move" {
  294. acl_pass_auth = "acl"
  295. if for_a == 0 {
  296. end_number += 1
  297. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_move_acl'"))
  298. if err != nil {
  299. log.Fatal(err)
  300. }
  301. defer stmt.Close()
  302. err = stmt.QueryRow(name).Scan(&acl_data)
  303. if err != nil {
  304. if err == sql.ErrNoRows {
  305. acl_data = ""
  306. } else {
  307. log.Fatal(err)
  308. }
  309. }
  310. } else {
  311. err := db.QueryRow(DB_change("select data from other where name = 'document_move_acl'")).Scan(&acl_data)
  312. if err != nil {
  313. if err == sql.ErrNoRows {
  314. acl_data = ""
  315. } else {
  316. log.Fatal(err)
  317. }
  318. }
  319. }
  320. } else if tool == "document_edit" {
  321. acl_pass_auth = "acl"
  322. if for_a == 0 {
  323. end_number += 1
  324. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_acl'"))
  325. if err != nil {
  326. log.Fatal(err)
  327. }
  328. defer stmt.Close()
  329. err = stmt.QueryRow(name).Scan(&acl_data)
  330. if err != nil {
  331. if err == sql.ErrNoRows {
  332. acl_data = ""
  333. } else {
  334. log.Fatal(err)
  335. }
  336. }
  337. } else {
  338. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_acl'")).Scan(&acl_data)
  339. if err != nil {
  340. if err == sql.ErrNoRows {
  341. acl_data = ""
  342. } else {
  343. log.Fatal(err)
  344. }
  345. }
  346. }
  347. } else if tool == "document_edit" {
  348. acl_pass_auth = "acl"
  349. if for_a == 0 {
  350. end_number += 1
  351. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_delete_acl'"))
  352. if err != nil {
  353. log.Fatal(err)
  354. }
  355. defer stmt.Close()
  356. err = stmt.QueryRow(name).Scan(&acl_data)
  357. if err != nil {
  358. if err == sql.ErrNoRows {
  359. acl_data = ""
  360. } else {
  361. log.Fatal(err)
  362. }
  363. }
  364. } else {
  365. err := db.QueryRow(DB_change("select data from other where name = 'document_delete_acl'")).Scan(&acl_data)
  366. if err != nil {
  367. if err == sql.ErrNoRows {
  368. acl_data = ""
  369. } else {
  370. log.Fatal(err)
  371. }
  372. }
  373. }
  374. } else if tool == "topic" {
  375. acl_pass_auth = "topic"
  376. if for_a == 0 {
  377. end_number += 1
  378. stmt, err := db.Prepare(DB_change("select acl from rd where code = ?"))
  379. if err != nil {
  380. log.Fatal(err)
  381. }
  382. defer stmt.Close()
  383. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  384. if err != nil {
  385. if err == sql.ErrNoRows {
  386. acl_data = ""
  387. } else {
  388. log.Fatal(err)
  389. }
  390. }
  391. } else if for_a == 1 {
  392. end_number += 1
  393. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'dis'"))
  394. if err != nil {
  395. log.Fatal(err)
  396. }
  397. defer stmt.Close()
  398. err = stmt.QueryRow(name).Scan(&acl_data)
  399. if err != nil {
  400. if err == sql.ErrNoRows {
  401. acl_data = ""
  402. } else {
  403. log.Fatal(err)
  404. }
  405. }
  406. } else {
  407. err := db.QueryRow(DB_change("select data from other where name = 'discussion'")).Scan(&acl_data)
  408. if err != nil {
  409. if err == sql.ErrNoRows {
  410. acl_data = ""
  411. } else {
  412. log.Fatal(err)
  413. }
  414. }
  415. }
  416. } else if tool == "topic_view" {
  417. acl_pass_auth = "topic"
  418. stmt, err := db.Prepare(DB_change("select set_data from topic_set where thread_code = ? and set_name = 'thread_view_acl'"))
  419. if err != nil {
  420. log.Fatal(err)
  421. }
  422. defer stmt.Close()
  423. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  424. if err != nil {
  425. if err == sql.ErrNoRows {
  426. acl_data = ""
  427. } else {
  428. log.Fatal(err)
  429. }
  430. }
  431. } else if tool == "upload" {
  432. acl_pass_auth = "multiple_upload"
  433. err := db.QueryRow(DB_change("select data from other where name = 'upload_acl'")).Scan(&acl_data)
  434. if err != nil {
  435. if err == sql.ErrNoRows {
  436. acl_data = ""
  437. } else {
  438. log.Fatal(err)
  439. }
  440. }
  441. } else if tool == "many_upload" {
  442. acl_pass_auth = "multiple_upload"
  443. err := db.QueryRow(DB_change("select data from other where name = 'many_upload_acl'")).Scan(&acl_data)
  444. if err != nil {
  445. if err == sql.ErrNoRows {
  446. acl_data = ""
  447. } else {
  448. log.Fatal(err)
  449. }
  450. }
  451. } else if tool == "vote" {
  452. acl_pass_auth = "vote_fix"
  453. if for_a == 0 {
  454. end_number += 1
  455. if topic_number != "" {
  456. stmt, err := db.Prepare(DB_change("select acl from vote where id = ? and user = ''"))
  457. if err != nil {
  458. log.Fatal(err)
  459. }
  460. defer stmt.Close()
  461. err = stmt.QueryRow(topic_number).Scan(&acl_data)
  462. if err != nil {
  463. if err == sql.ErrNoRows {
  464. acl_data = ""
  465. } else {
  466. log.Fatal(err)
  467. }
  468. }
  469. } else {
  470. continue
  471. }
  472. } else {
  473. err := db.QueryRow(DB_change("select data from other where name = 'vote_acl'")).Scan(&acl_data)
  474. if err != nil {
  475. if err == sql.ErrNoRows {
  476. acl_data = ""
  477. } else {
  478. log.Fatal(err)
  479. }
  480. }
  481. }
  482. } else if tool == "slow_edit" {
  483. acl_pass_auth = "slow_edit_pass"
  484. err := db.QueryRow(DB_change("select data from other where name = 'slow_edit_acl'")).Scan(&acl_data)
  485. if err != nil {
  486. if err == sql.ErrNoRows {
  487. acl_data = ""
  488. } else {
  489. log.Fatal(err)
  490. }
  491. }
  492. } else if tool == "edit_bottom_compulsion" {
  493. acl_pass_auth = "edit_bottom_compulsion_pass"
  494. err := db.QueryRow(DB_change("select data from other where name = 'edit_bottom_compulsion_acl'")).Scan(&acl_data)
  495. if err != nil {
  496. if err == sql.ErrNoRows {
  497. acl_data = ""
  498. } else {
  499. log.Fatal(err)
  500. }
  501. }
  502. } else if tool == "bbs_edit" {
  503. acl_pass_auth = "bbs"
  504. if for_a == 0 {
  505. end_number += 1
  506. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl' and set_id = ?"))
  507. if err != nil {
  508. log.Fatal(err)
  509. }
  510. defer stmt.Close()
  511. err = stmt.QueryRow(name).Scan(&acl_data)
  512. if err != nil {
  513. if err == sql.ErrNoRows {
  514. acl_data = ""
  515. } else {
  516. log.Fatal(err)
  517. }
  518. }
  519. } else if for_a == 1 {
  520. end_number += 1
  521. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  522. if err != nil {
  523. log.Fatal(err)
  524. }
  525. defer stmt.Close()
  526. err = stmt.QueryRow(name).Scan(&acl_data)
  527. if err != nil {
  528. if err == sql.ErrNoRows {
  529. acl_data = ""
  530. } else {
  531. log.Fatal(err)
  532. }
  533. }
  534. } else if for_a == 2 {
  535. end_number += 1
  536. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_edit_acl_all'")).Scan(&acl_data)
  537. if err != nil {
  538. if err == sql.ErrNoRows {
  539. acl_data = ""
  540. } else {
  541. log.Fatal(err)
  542. }
  543. }
  544. } else {
  545. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  546. if err != nil {
  547. if err == sql.ErrNoRows {
  548. acl_data = ""
  549. } else {
  550. log.Fatal(err)
  551. }
  552. }
  553. }
  554. } else if tool == "bbs_comment" {
  555. acl_pass_auth = "bbs"
  556. if for_a == 0 {
  557. end_number += 1
  558. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl' and set_id = ?"))
  559. if err != nil {
  560. log.Fatal(err)
  561. }
  562. defer stmt.Close()
  563. err = stmt.QueryRow(name).Scan(&acl_data)
  564. if err != nil {
  565. if err == sql.ErrNoRows {
  566. acl_data = ""
  567. } else {
  568. log.Fatal(err)
  569. }
  570. }
  571. } else if for_a == 1 {
  572. end_number += 1
  573. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_acl' and set_id = ?"))
  574. if err != nil {
  575. log.Fatal(err)
  576. }
  577. defer stmt.Close()
  578. err = stmt.QueryRow(name).Scan(&acl_data)
  579. if err != nil {
  580. if err == sql.ErrNoRows {
  581. acl_data = ""
  582. } else {
  583. log.Fatal(err)
  584. }
  585. }
  586. } else if for_a == 2 {
  587. end_number += 1
  588. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_comment_acl_all'")).Scan(&acl_data)
  589. if err != nil {
  590. if err == sql.ErrNoRows {
  591. acl_data = ""
  592. } else {
  593. log.Fatal(err)
  594. }
  595. }
  596. } else {
  597. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_acl_all'")).Scan(&acl_data)
  598. if err != nil {
  599. if err == sql.ErrNoRows {
  600. acl_data = ""
  601. } else {
  602. log.Fatal(err)
  603. }
  604. }
  605. }
  606. } else if tool == "bbs_view" {
  607. acl_pass_auth = "bbs"
  608. if for_a == 0 {
  609. end_number += 1
  610. stmt, err := db.Prepare(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl' and set_id = ?"))
  611. if err != nil {
  612. log.Fatal(err)
  613. }
  614. defer stmt.Close()
  615. err = stmt.QueryRow(name).Scan(&acl_data)
  616. if err != nil {
  617. if err == sql.ErrNoRows {
  618. acl_data = ""
  619. } else {
  620. log.Fatal(err)
  621. }
  622. }
  623. } else {
  624. err := db.QueryRow(DB_change("select set_data from bbs_set where set_name = 'bbs_view_acl_all'")).Scan(&acl_data)
  625. if err != nil {
  626. if err == sql.ErrNoRows {
  627. acl_data = ""
  628. } else {
  629. log.Fatal(err)
  630. }
  631. }
  632. }
  633. } else if tool == "recaptcha" {
  634. acl_pass_auth = "captcha_pass"
  635. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_pass_acl'")).Scan(&acl_data)
  636. if err != nil {
  637. if err == sql.ErrNoRows {
  638. acl_data = ""
  639. } else {
  640. log.Fatal(err)
  641. }
  642. }
  643. } else if tool == "recaptcha_five_pass" {
  644. acl_pass_auth = "captcha_one_check_five_pass"
  645. err := db.QueryRow(DB_change("select data from other where name = 'recaptcha_one_check_five_pass_acl'")).Scan(&acl_data)
  646. if err != nil {
  647. if err == sql.ErrNoRows {
  648. acl_data = ""
  649. } else {
  650. log.Fatal(err)
  651. }
  652. }
  653. } else if tool == "document_edit_request" {
  654. acl_pass_auth = "acl"
  655. if for_a == 0 {
  656. end_number += 1
  657. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'document_edit_request_acl'"))
  658. if err != nil {
  659. log.Fatal(err)
  660. }
  661. defer stmt.Close()
  662. err = stmt.QueryRow(name).Scan(&acl_data)
  663. if err != nil {
  664. if err == sql.ErrNoRows {
  665. acl_data = ""
  666. } else {
  667. log.Fatal(err)
  668. }
  669. }
  670. } else {
  671. err := db.QueryRow(DB_change("select data from other where name = 'document_edit_request_acl'")).Scan(&acl_data)
  672. if err != nil {
  673. if err == sql.ErrNoRows {
  674. acl_data = ""
  675. } else {
  676. log.Fatal(err)
  677. }
  678. }
  679. }
  680. } else if tool == "document_make_acl" {
  681. acl_pass_auth = "acl"
  682. err := db.QueryRow(DB_change("select data from other where name = 'document_make_acl'")).Scan(&acl_data)
  683. if err != nil {
  684. if err == sql.ErrNoRows {
  685. acl_data = ""
  686. } else {
  687. log.Fatal(err)
  688. }
  689. }
  690. } else {
  691. // tool == "render"
  692. acl_pass_auth = "acl"
  693. if for_a == 0 {
  694. end_number += 1
  695. stmt, err := db.Prepare(DB_change("select data from acl where title = ? and type = 'view'"))
  696. if err != nil {
  697. log.Fatal(err)
  698. }
  699. defer stmt.Close()
  700. err = stmt.QueryRow(name).Scan(&acl_data)
  701. if err != nil {
  702. if err == sql.ErrNoRows {
  703. acl_data = ""
  704. } else {
  705. log.Fatal(err)
  706. }
  707. }
  708. } else {
  709. err := db.QueryRow(DB_change("select data from other where name = 'all_view_acl'")).Scan(&acl_data)
  710. if err != nil {
  711. if err == sql.ErrNoRows {
  712. acl_data = ""
  713. } else {
  714. log.Fatal(err)
  715. }
  716. }
  717. }
  718. }
  719. if auth_info[acl_pass_auth] {
  720. return true
  721. } else if ban_type == "4" {
  722. return false
  723. }
  724. if acl_data == "" {
  725. if tool == "recaptcha" {
  726. acl_data = "admin"
  727. } else if tool == "slow_edit" || tool == "edit_bottom_compulsion" {
  728. acl_data = "not_all"
  729. } else {
  730. acl_data = "normal"
  731. }
  732. }
  733. except_ban_tool_list := []string{"render", "topic_view", "bbs_view"}
  734. if acl_data != "normal" {
  735. if !(acl_data == "ban" || acl_data == "ban_admin") || ban_type == "3" {
  736. if !Arr_in_str(except_ban_tool_list, tool) {
  737. if get_ban == "true" {
  738. return false
  739. }
  740. }
  741. }
  742. if acl_data == "all" || acl_data == "ban" {
  743. return true
  744. } else if acl_data == "user" {
  745. if !ip_or_user {
  746. return true
  747. }
  748. } else if acl_data == "admin" {
  749. if auth_info["treat_as_admin"] {
  750. return true
  751. }
  752. } else if acl_data == "50_edit" {
  753. if !ip_or_user {
  754. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  755. if err != nil {
  756. log.Fatal(err)
  757. }
  758. defer stmt.Close()
  759. var count int
  760. err = stmt.QueryRow(ip).Scan(&count)
  761. if err != nil {
  762. if err == sql.ErrNoRows {
  763. count = 0
  764. } else {
  765. log.Fatal(err)
  766. }
  767. }
  768. if count >= 50 {
  769. return true
  770. }
  771. }
  772. } else if acl_data == "before" {
  773. stmt, err := db.Prepare(DB_change("select ip from history where title = ? and ip = ?"))
  774. if err != nil {
  775. log.Fatal(err)
  776. }
  777. defer stmt.Close()
  778. var exist string
  779. err = stmt.QueryRow(name, ip).Scan(&exist)
  780. if err != nil {
  781. if err == sql.ErrNoRows {
  782. exist = ""
  783. } else {
  784. log.Fatal(err)
  785. }
  786. }
  787. if exist != "" {
  788. return true
  789. }
  790. } else if acl_data == "30_day" || acl_data == "90_day" {
  791. if !ip_or_user {
  792. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  793. if err != nil {
  794. log.Fatal(err)
  795. }
  796. defer stmt.Close()
  797. var signup_date string
  798. err = stmt.QueryRow(ip).Scan(&signup_date)
  799. if err != nil {
  800. if err == sql.ErrNoRows {
  801. signup_date = Get_time()
  802. } else {
  803. log.Fatal(err)
  804. }
  805. }
  806. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  807. if acl_data == "30_day" {
  808. time_1 = time_1.AddDate(0, 0, 30)
  809. } else {
  810. time_1 = time_1.AddDate(0, 0, 90)
  811. }
  812. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  813. if time_2.After(time_1) {
  814. return true
  815. }
  816. }
  817. } else if acl_data == "email" {
  818. if !ip_or_user {
  819. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'email'"))
  820. if err != nil {
  821. log.Fatal(err)
  822. }
  823. defer stmt.Close()
  824. var exist string
  825. err = stmt.QueryRow(ip).Scan(&exist)
  826. if err != nil {
  827. if err == sql.ErrNoRows {
  828. exist = ""
  829. } else {
  830. log.Fatal(err)
  831. }
  832. }
  833. if exist != "" {
  834. return true
  835. }
  836. }
  837. } else if acl_data == "owner" {
  838. if auth_info["owner"] {
  839. return true
  840. }
  841. } else if acl_data == "ban_admin" {
  842. if auth_info["treat_as_admin"] || get_ban == "true" {
  843. return true
  844. }
  845. } else if acl_data == "not_all" {
  846. return false
  847. } else if acl_data == "up_to_level_3" || acl_data == "up_to_level_10" {
  848. if acl_data == "up_to_level_3" {
  849. if level_int >= 3 {
  850. return true
  851. }
  852. } else if acl_data == "up_to_level_10" {
  853. if level_int >= 10 {
  854. return true
  855. }
  856. }
  857. } else if acl_data == "30_day_50_edit" {
  858. if !ip_or_user {
  859. stmt, err := db.Prepare(DB_change("select data from user_set where id = ? and name = 'date'"))
  860. if err != nil {
  861. log.Fatal(err)
  862. }
  863. defer stmt.Close()
  864. var signup_date string
  865. err = stmt.QueryRow(ip).Scan(&signup_date)
  866. if err != nil {
  867. if err == sql.ErrNoRows {
  868. signup_date = Get_time()
  869. } else {
  870. log.Fatal(err)
  871. }
  872. }
  873. time_1, _ := time.Parse("2006-01-02 15:04:05", signup_date)
  874. time_1 = time_1.AddDate(0, 0, 30)
  875. time_2, _ := time.Parse("2006-01-02 15:04:05", Get_time())
  876. if time_2.After(time_1) {
  877. stmt, err := db.Prepare(DB_change("select count(*) from history where ip = ?"))
  878. if err != nil {
  879. log.Fatal(err)
  880. }
  881. defer stmt.Close()
  882. var count int
  883. err = stmt.QueryRow(ip).Scan(&count)
  884. if err != nil {
  885. if err == sql.ErrNoRows {
  886. count = 0
  887. } else {
  888. log.Fatal(err)
  889. }
  890. }
  891. if count >= 50 {
  892. return true
  893. }
  894. }
  895. }
  896. }
  897. return false
  898. } else if for_a == end_number-1 {
  899. if !Arr_in_str(except_ban_tool_list, tool) {
  900. if get_ban == "true" {
  901. return false
  902. }
  903. }
  904. if tool == "topic" {
  905. stmt, err := db.Prepare(DB_change("select title from rd where code = ? and stop != ''"))
  906. if err != nil {
  907. log.Fatal(err)
  908. }
  909. defer stmt.Close()
  910. var topic_state string
  911. err = stmt.QueryRow(topic_number).Scan(&topic_state)
  912. if err != nil {
  913. if err == sql.ErrNoRows {
  914. topic_state = ""
  915. } else {
  916. log.Fatal(err)
  917. }
  918. }
  919. if topic_state != "" {
  920. if auth_info["topic"] {
  921. return true
  922. } else {
  923. return false
  924. }
  925. } else {
  926. return true
  927. }
  928. } else {
  929. return true
  930. }
  931. }
  932. }
  933. return false
  934. }